CVE-2016-5016
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13…
Does this matter?
Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.
Description
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- pivotal software/cloud foundry · pivotal software/cloud foundry elastic runtime · pivotal software/cloud foundry uaa · pivotal software/cloud foundry uaa-release
- Source
- secalert@redhat.com
References
- https://github.com/cloudfoundry/cf-release/releases/tag/v240Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v11.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v12.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.6Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.3.0.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.4.2Release Notes, Third Party Advisory
- https://pivotal.io/security/cve-2016-5016Vendor Advisory
- https://github.com/cloudfoundry/cf-release/releases/tag/v240Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v11.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v12.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.6Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.3.0.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.4.2Release Notes, Third Party Advisory
- https://pivotal.io/security/cve-2016-5016Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.